All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Chainguard sells hardened, near-zero-CVE builds of open source as drop-in replacements that engineering teams adopt by repointing compatible images. Gartner named it a Leader in the inaugural software supply chain security quadrant, placed furthest for vision, more than 150 customers and a sevenfold revenue jump to forty million dollars back the traction, and its build factory has processed more than a billion build manifests. Durability is the weak point. Compatible images swap back while others need migration work, Docker ships competing hardened images, and six hundred twelve million dollars raised against forty million in ARR, both reported at the April 2025 Series D, is a steep bar, so the edge is brand, catalog breadth, and a remediation commitment rather than lock-in.
| Description | Delivers hardened, minimal, continuously rebuilt container images, open-source libraries, and virtual machine images with near-zero known vulnerabilities, signed SBOMs, and a contractual CVE remediation SLA, as drop-in replacements for the upstream open source that engineering teams run. | [f1] |
|---|---|---|
| Founded | 2021 | [f2] |
| HQ | Kirkland, Washington (remote-first) | [f3] |
| Funding | $892M total | [f3] |
| Latest funding | $280M growth financing from General Catalyst (October 2025); prior Series D $356M at $3.5B valuation (April 2025) | [f3] |
| Product | What it does |
|---|---|
| Chainguard Containers | Minimal, secure-by-design container images rebuilt from source with FIPS cryptography, OS-level STIGs, and full SBOMs, guarded under a contractual CVE remediation SLA. |
| Chainguard Libraries | Hardened builds of open-source language libraries that extend the CVE-free promise to application dependencies and guard against malware in registries such as npm and PyPI. |
| Chainguard VMs | Minimal, secure-by-design virtual machine images for base, app, and container-host deployments, licensed per image or by engineering organization size under a contractual CVE SLA. |
| Chainguard Guardener | AI-powered continuous-maintenance agent that migrates Dockerfiles to Chainguard artifacts and rebuilds them from source across CI/CD systems, extending the build factory to customer pipelines. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Hardened, near-zero-CVE images, libraries, and VM builds replace vulnerable upstream open-source components across container workloads and application dependencies. The products protect conventional software infrastructure, so the company is mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Chainguard names a specific buyer, the engineering teams that maintain open source rather than CISOs, and quantifies the pain at roughly 97.6% fewer vulnerabilities and 80% lower CVE accumulation, with its own SOC 2 audit citing the patching toil a typical estate carries. Independent press and independent technical coverage frame the same problem. [s2, s5, s7, s13] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 5/5 | A publicly browsable directory of more than 2,000 images with FIPS and STIG variants, signed SBOMs, Sigstore signatures, and a SLSA L3 build factory is independently inspectable, The New Stack documents the from-source rebuild mechanism as a genuine technical departure, and Gartner placed Chainguard furthest for vision, validation beyond marketing. [s2, s3, s4, s12, s11] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Gartner stood up its first software supply chain security quadrant in 2026 and independent coverage ties demand to AI code generation expanding the artifact estate faster than teams can maintain it, multiple buyer-side signals that place timing at 4. The window could close if registry owners ship hardened images as a default before the standalone catalog locks customers in. [s11, s13, s14] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Co-founders Dan Lorenc and Matt Moore were software engineers at Google and Microsoft, Lorenc spent nine years on Google Cloud infrastructure, and the team has built Chainguard into a Gartner-recognized leader in four years, verifiable in-domain pedigree and a delivered build multiply evidenced across Fortune, SecurityWeek, and The New Stack. [s7, s9, s12] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Independent press names more than 150 customers as of April 2025 including Hewlett Packard Enterprise, GitLab, ANZ Bank, Canva, and Wiz across multiple outlets, but the sevenfold revenue jump to forty million dollars is vendor-reported and relayed rather than independently confirmed, so traction clears the named-reference bar without the independent scale confirmation a 5 needs. [s7, s8, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Revenue grew sevenfold to forty million dollars while the catalog roughly tripled, visible output, and the General Catalyst tranche is non-dilutive and unlocked only as customers are acquired, a discipline signal, but the six hundred twelve million dollars raised as of that April 2025 round leaves efficiency unconfirmed rather than demonstrated against the same-date revenue. The later two hundred eighty million dollar facility carries no updated revenue figure alongside it. [s9, s7, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 5/5 | Chainguard was named a Leader in Gartner's inaugural Magic Quadrant for software supply chain security and placed furthest for Completeness of Vision, an independently reported third-party placement, and independent technical press treats it as a leading vendor in the category, so buyers and analysts place it without vendor coaching. [s11, s13] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Operating a multi-thousand-image rebuild factory under a contractual SLA is more than a quarterly feature, but Docker ships its own hardened images, cloud registries can bundle hardened variants into existing subscriptions, and the standard OCI artifacts carry no system-of-record lock-in, so no moat an incumbent could not replicate is visible. [s13, s3, s2] |
Chainguard sells the removal of inherited vulnerabilities from the software supply chain rather than another tool for finding them. It reports its images carry roughly 97.6% fewer vulnerabilities and about 80% lower CVE accumulation over time than typical alternatives, and its own SOC 2 writeup describes the toil it removes, noting a typical estate of 70 services in production can total 14,000 vulnerabilities to track and remediate.
The buyer is unusual for security and named plainly. Fortune reports that Chainguard does not primarily sell to CISOs but to the engineering teams that build and maintain open source, which reframes the purchase as developer productivity as much as risk reduction. Independent press across the funding rounds relays the same framing.
The backdrop is current and independently observed. The New Stack frames the rise of zero-CVE images as a baseline expectation for containerized workloads, and ties the urgency to AI-generated code expanding the artifact estate faster than teams can maintain it by hand. [s2, s5, s7, s13]
Chainguard ships families of prebuilt, hardened artifacts rather than a scanner. The catalog spans container images, language libraries, and virtual machine images, with FIPS-cryptography and OS-level STIG variants for compliance-bound customers, and adoption is a low-friction change because a team repoints its builds at Chainguard's registry as a drop-in OCI source.
The build mechanic is continuous reconstruction rather than patching. The New Stack documents Chainguard rebuilding containers and libraries directly from source, every artifact ships with Sigstore signatures and a signed SBOM, and a SLSA L3 build factory underpins the provenance. A contractual CVE remediation SLA commits the company to seven days for critical and fourteen days for other severities.
Public verifiability is the capability exhibit. A browsable directory lists more than 2,000 images across base, application, AI, and FIPS categories, a free tier offers up to five images, and a 4.8 G2 rating reflects reviewed buyer sentiment. Gartner placing Chainguard furthest for vision is third-party validation the directory and rivals corroborate. [s2, s3, s4, s11, s12, s13]
Chainguard is a leading vendor in hardened minimal images. Gartner named it a Leader in the inaugural software supply chain security quadrant and placed it furthest for vision, and independent technical press treats it as a leading zero-CVE vendor.
The adjacency that matters most over time is Docker and the cloud registries. Docker now ships its own hardened images, and the registries that distribute Chainguard's artifacts are the same channels an incumbent could use to bundle a competing hardened catalog into subscriptions buyers already hold. That is the structural pressure on the standalone catalog.
Against direct rivals the contest is breadth and price. Echo and Minimus are hardened minimal-image alternatives pursuing the same near-zero-CVE buyer, while Chainguard counters with catalog breadth, a contractual SLA, and a compliance track record, so the competition runs on who sustains quality and coverage at a price enterprises accept. [s11, s13, s3]
Chainguard runs an enterprise motion with a free entry tier feeding paid expansion. Pricing is published in structure, with a free five-image tier, per-image production licensing, and a catalog plan starting at nineteen thousand dollars for a team of ten, while enterprise deals route through a quote.
Named traction spans press and the vendor's own pages. GeekWire and Fortune report more than 150 customers at the Series D, including ANZ Bank, Canva, GitLab, Hewlett Packard Enterprise, VPBank, and Wiz, and recurring revenue grew sevenfold to forty million dollars with a stated target above one hundred million by the end of fiscal 2026. The mix of independent and self-reported evidence is unusually deep for the category.
Growth capital, not just equity, backs the motion. The General Catalyst financing is non-dilutive and unlocked only as customers are acquired, which lets the company scale go-to-market spend without a priced equity round, though retention and per-customer economics stay undisclosed. [s3, s7, s8, s9, s10]
Chainguard's founders carry verifiable infrastructure pedigree. The New Stack reports that CEO Dan Lorenc and CTO Matt Moore were software engineers at Google and Microsoft, with Moore also at VMware, and that Chief Product Officer Kim Lewandowski and Distinguished Engineer Ville Aikas also came through Google and VMware. Fortune notes Lorenc spent nine years on Google Cloud infrastructure before founding the company.
Execution has matched the pedigree. The company grew its catalog from roughly 400 to well over a thousand images and revenue from five million to forty million dollars in a single year, and it now carries a Gartner Leader placement, so the team has converted infrastructure experience into a recognized category position.
The bench behind the motion is public. A president recruited from Wiz fronts go-to-market and a named CFO fronts the growth-financing strategy, so the executive team behind a fast-scaling enterprise motion is visible rather than implied. [s7, s9, s12]
Chainguard leads with the attestations its compliance-driven buyers check, and it holds its own SOC 2 certification, which it says it eased by dogfooding Chainguard Images to cut CVEs during the audit. Every image ships with Sigstore signatures and a signed SBOM that auditors verify independently.
The product is positioned as the easy path to the customer's own federal mandates. HireVue credits Chainguard with securing its path to FedRAMP authorization, having previously had roughly 30% of a cloud engineering team consumed by recurring patching. The federal angle serves the buyer's mandate rather than functioning as a Chainguard authorization, since no Chainguard federal authorization of its own appears in reviewed pages.
The deeper trust question is concentration, and independent coverage sharpens it. Customers source foundational software from one vendor's build pipeline, and The New Stack notes that CVE counts are a useful but imperfect measure of safety, so the verifiable provenance chain, not a published third-party audit of the pipeline, is the public answer. [s5, s6, s13]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Echo | competes with | Hardened minimal-image vendor pursuing the same near-zero-CVE image buyer as Chainguard. | |
| Docker | competes with | Publisher of the upstream images Chainguard replaces that now ships its own Docker Hardened Images, pairing a competing product with the registry distribution position to bundle hardened alternatives into existing subscriptions. | |
| Minimus | competes with | Minimal, near-zero-CVE container image vendor positioned as a hardened-image alternative to Chainguard. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Chainguard.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Chainguard is durable where its artifacts become the base layer of customer software and exposed where switching is cheap. Compliance-bound enterprises buy those artifacts, and the contractual remediation commitment is the accountability they pay for. The design that won the category also limits lock-in, because compatible images swap back while others need migration work, Docker ships competing hardened images, and the rebuild factory works on public upstreams, not a proprietary dataset. The compliance positioning is a feature serving the buyer's federal authorizations, since Chainguard's own attestation is commercial SOC 2. The hardest asset to take is the engineering depth behind the from-source factory, recognized by Gartner's vision placement, not the catalog it produces.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers pull hardened artifacts and run them themselves under a contractual CVE SLA, automated remediation delivered as software output rather than a service in which Chainguard accepts accountability for the customer's security outcome. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Chainguard distributes standard OCI artifacts through registries customers already use, so compatible images can be swapped back quickly while others need Dockerfile, package, and test changes, and customers also re-establish FIPS and STIG evidence and re-tune scanner integrations, real but modest friction. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Chainguard's own attestation is commercial SOC 2, and its FedRAMP, STIG, and FIPS materials accelerate the customer's authorizations rather than representing a federal authorization Chainguard itself holds, so the compliance assets are a product feature. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building a custom undistro and a from-source rebuild factory that has processed more than a billion build manifests with SLSA L3 provenance is specialized engineering accumulated over years, which The New Stack documents as a genuine departure from building images atop full operating systems. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Named customers are enterprises, several with federal compliance obligations such as HireVue's FedRAMP path, and quote-gated catalog pricing implies procurement-mediated deals, an enterprise buyer base that carries the gates slowing commodity substitution even though adoption is engineering-led. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Base images, libraries, and VM builds are the layer applications are built on, and Chainguard's artifacts become part of the customer's running software rather than a tool observing it from outside. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The maintained catalog and build factory are real engineering, but they rebuild public upstream open source rather than a named non-public dataset, and competing hardened-image offerings show the asset is replicable rather than a proprietary moat. |
Chainguard targets engineering organizations that inherit vulnerability debt from open-source infrastructure, with compliance-bound and federal-adjacent buyers as a visible high-value segment. The named customers span finance, technology, and software, including Hewlett Packard Enterprise, GitLab, ANZ Bank, Canva, VPBank, and Wiz, a breadth that signals the problem cuts across regulated and unregulated industries.
The buyer identity is unusual and explicit. Fortune reports that Chainguard sells not to CISOs but to the engineering teams that build and maintain open source, so the purchase is framed as engineering productivity as much as risk reduction. That widens the top of the funnel but also means adoption is developer-led rather than mandated from a security budget.
Deal sizing and demand are public enough to gauge. The catalog plan starts at nineteen thousand dollars for a team of ten and scales by engineering-organization size, more than 150 customers are named or counted across independent press as of April 2025, and recurring revenue grew sevenfold to forty million dollars in fiscal 2025, so the segment is large and actively buying.
Chainguard's product claim is subtraction, since artifacts arrive without the vulnerabilities other vendors help customers find. The catalog spans container images, language libraries, and VM builds, with FIPS-cryptography and OS-level STIG variants, and the headline figures are roughly 97.6% fewer vulnerabilities and about 80% lower CVE accumulation over time than typical alternatives.
The build mechanic is continuous reconstruction with verifiable provenance. The New Stack documents Chainguard rebuilding containers and libraries directly from source, every artifact ships with cryptographic signatures and a signed SBOM, and a SLSA L3 build factory that has processed more than a billion build manifests underpins the chain. A contractual CVE remediation SLA commits the company to seven days for critical flaws.
The advantage is breadth and operating maturity rather than a proprietary dataset. A browsable directory lists more than 2,000 images across base, application, AI, and FIPS categories, the catalog roughly tripled in a year, and Gartner placed Chainguard furthest for vision. A rival with comparable engineering can build a catalog, so the edge is the size, currency, and provenance depth of the one Chainguard already runs.
Chainguard sells an enterprise motion with a free tier feeding paid expansion. A free five-image tier and a published catalog price that starts at nineteen thousand dollars route smaller teams into self-service, while production and catalog-wide deals go through a quote, and the later financing unlocks capital as customers are acquired to fund that growth.
Distribution rides infrastructure customers already operate. Chainguard's artifacts are pulled from its own registry or mirrored into the artifact managers enterprises already run, and verified by the scanners that would otherwise flag findings, which removes adoption friction, though none of those channels would resist a well-funded rival since registries distribute anyone's artifacts.
Traction evidence is unusually deep for the category and still thin on unit economics. Independent press names more than 150 customers as of April 2025 and reports the sevenfold revenue jump to forty million dollars, but retention, net expansion, and per-customer economics stay undisclosed, so the repeatability of the motion beyond the named accounts is not fully verifiable in public.
Chainguard publishes its packaging logic and an entry price, unlike most rivals. The catalog plan is licensed by engineering-organization size and starts at nineteen thousand dollars for a team of ten, a per-image production plan is licensed by the number and type of images including base, app, AI, and FIPS, and a free tier covers up to five images.
Both paid units track how the buyer measures the problem. Images consumed equal the dependency surface being secured, and engineering-organization size scales with how much software the customer builds, and the company states catalog pricing scales non-linearly so cost does not double when a team doubles. Chainguard charges by the units customers use to size their own exposure.
The premium question stays partly open. The published entry price anchors expectations, but enterprise and catalog-wide deals are quote-gated, and reviewed pages do not position Chainguard's cost against the internal cost of a patching team beyond the CVE-reduction outcome claims.
Delivery is registry-native and demands almost no deployment. Chainguard ships standard OCI artifacts that customers pull from its registry or mirror into the artifact managers they already operate, so customers point their builds at Chainguard's images and let their existing scanners verify the result, with a free tier available to test in production before committing.
Operations carry the product's substance. Chainguard rebuilds images continuously from source in a SLSA L3 factory, commits to remediation under a contractual CVE SLA of seven days for critical flaws, and ships signed SBOMs and provenance with each artifact, which turns the delivered artifact into ongoing maintenance rather than a one-time download.
The failure modes are asymmetric. A Chainguard outage leaves customers running but freezes their patch supply, while a compatibility regression in a rebuilt artifact would surface as a customer production incident, which is why minimality and rebuild discipline are the operational core, and reviewed pages do not publish an uptime or support-tier commitment.
Chainguard's certifications match its buyers' strict procurement reviews, and it holds its own SOC 2 certification, which it says it eased by dogfooding Chainguard Images to cut CVEs during the audit. Every artifact ships with cryptographic signatures and a signed SBOM that auditors verify independently, so the compliance evidence is built into the product.
The federal story is a feature, not the company's own authorization. HireVue credits Chainguard with securing its path to FedRAMP authorization, having previously had roughly 30% of a cloud engineering team consumed by recurring patching, but reviewed pages show no FedRAMP authorization that Chainguard itself holds, so the compliance positioning serves the buyer's mandate rather than functioning as Chainguard's moat.
The deeper trust question is concentration, and independent coverage sharpens it. Customers source foundational software from one vendor's build pipeline, and The New Stack notes that CVE counts are a useful but imperfect measure of safety, so the verifiable provenance chain, not a published third-party audit of the pipeline, is the public answer.
Chainguard runs its own registry and management console and wires them into the container ecosystem customers already operate. Customers pull artifacts directly from Chainguard's registry or mirror them into artifact managers such as JFrog Artifactory, Harbor, and Amazon ECR, and Chainguard partners with the vulnerability scanners customers already run, including Snyk, Trivy, Wiz, and CrowdStrike, so the company sits inside existing workflows rather than asking buyers to leave them.
The stated ambition is to be the trusted source the rest of the stack depends on. The catalog now spans base, application, AI, and FIPS images, and Chainguard introduced the Guardener, an agent that migrates Dockerfiles to its artifacts and continuously rebuilds them, which RedMonk frames as a response to AI code generation expanding the maintenance burden. That sketches a move from image catalog toward a broader trusted-software foundation.
Ecosystem dependencies cut both ways. Chainguard depends on the upstream open-source projects it repackages and on registry and scanner cooperation it does not control, and Docker now ships its own hardened images, so a registry owner is simultaneously a distribution channel and a direct competitor with the position to bundle a competing hardened catalog.
Chainguard's founders carry verifiable infrastructure pedigree. The New Stack reports that CEO Dan Lorenc and CTO Matt Moore were software engineers at Google and Microsoft, with Moore also at VMware, that Chief Product Officer Kim Lewandowski also came through Google, and that Distinguished Engineer Ville Aikas has Google and VMware on his resume. Fortune notes Lorenc worked the better part of a decade at Google before founding the company.
Execution has matched the pedigree. The company grew its catalog from roughly 400 to well over a thousand images and revenue from five million to forty million dollars in a single year, and it now carries a Gartner Leader placement, so the team has converted infrastructure experience into a recognized category position.
The bench behind the motion is public. A president recruited from Wiz fronts go-to-market, so the executive bench behind a fast-scaling enterprise motion is visible, with capital efficiency the main open question against the six hundred twelve million dollars raised through the April 2025 Series D plus a later performance-based facility that unlocks as customers land.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Chainguard homepage | official | 2026-06-20 |
| f2 | GeekWire: Chainguard lands $356M, now valued at $3.5B | press | 2026-06-28 |
| f3 | GeekWire: Chainguard lands $280M to scale open source software protections | press | 2026-06-20 |
| f4 | Chainguard Containers product page | official | 2026-06-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Chainguard homepage “Building from source in a SLSA L3-compliant Factory is how Chainguard ensures that every line is verified, hardened, and traceable.” | official | 2026-06-28 |
| s2 | Chainguard Containers product page “4.8 Stars on G2 ... On average, Chainguard images show ~97.6% fewer vulnerabilities than typical alternatives, and ~80% lower CVE accumulation over time.” | official | 2026-06-28 |
| s3 | Chainguard pricing page “Full access to 2,000+ images (and growing) ... Starts at $19K for a team of 10 ... Contractual CVE SLA (7 days for critical, 14 days for high/med/low) ... Access to STIG-hardened and FIPS-validated images.” | official | 2026-06-28 |
| s4 | Chainguard Image Directory “Search. Pull. Build. ... Categories: All, Featured, Free, AI, Application, Base, Commercial, FIPS, MCP” | official | 2026-06-28 |
| s5 | Chainguard SOC 2 customer story “we saw a unique opportunity to practice what we preach by using our own product for our SOC 2 certification, Chainguard Images, which cut common vulnerabilities and exposures (CVEs) on average by 97.6%.” | official | 2026-06-28 |
| s6 | HireVue FedRAMP customer story “When Hirevue needed to achieve FedRAMP authorization for its core platform ... One of Hirevue's three cloud engineering delivery teams, approximately 30% of that workforce, was dedicated to recurring security patching and maintenance tasks.” | official | 2026-06-28 |
| s7 | Fortune: Chainguard secures $356 million Series D as valuation soars to $3.5 billion “In fiscal 2025, Chainguard grew its ARR sevenfold, reaching $40 million. By the end of fiscal 2026, it expects to ... hitting $100 million ... it counts over 150 customers, including Canva, HPE, and GitLab ... its buyers are the engineering teams building and maintaining open source.” | press | 2026-06-28 |
| s8 | GeekWire: Chainguard lands $356M, now valued at $3.5B “Chainguard raised $140 million in a Series C round at a $1.12 billion valuation less than a year ago. The company has raised $612 million to date ... It has more than 150 customers, including ANZ Bank, Canva, GitLab, Hewlett Packard Enterprise, VPBank, and Wiz.” | press | 2026-06-28 |
| s9 | SecurityWeek: Chainguard Raises Hefty $356M Series D at $3.5 Billion Valuation “Chainguard, a start-up created by ex-Google software engineers ... The cash infusion brings Chainguard's total funding to about $612 million since its $5 million seed in 2021 ... its catalog has grown from 400 to 1,400 images in the past year, pushing revenue from $5 million to $40 million.” | press | 2026-06-28 |
| s10 | BankInfoSecurity: Chainguard Banks $280M for Global Open-Source Security Play “The latest growth financing is non-dilutive and performance-based, meaning that capital is unlocked as Chainguard acquires customers ... a broader platform including virtual machines and secure libraries enables cross-selling.” | press | 2026-06-28 |
| s11 | SecurityBrief: Chainguard named Gartner leader in software supply security “Chainguard has been named a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security and was placed furthest right for Completeness of Vision ... Chainguard Factory ... has processed more than 1 billion unique build manifests.” | press | 2026-06-28 |
| s12 | The New Stack: Clean Container Images, A Supply Chain Security Revolution “CEO Dan Lorenc and CTO Matt Moore made software engineering stops at Google and Microsoft, with Moore also landing for a while at VMware, and Chief Product Officer Kim Lewandowski also did time with Google. Similarly, Distinguished Engineer Ville Aikas has Google and VMware on his resume.” | press | 2026-06-28 |
| s13 | The New Stack: The hunt for truly zero-CVE container images “Chainguard, one of the leading zero-CVE container image vendors, uses its new software, Factory 2.0, and its DriftlessAF open-source approach to rebuild containers and libraries directly from source ... CVEs remain a useful, but imperfect metric, for measuring safety.” | press | 2026-06-28 |
| s14 | Computer Weekly: Chainguard tightens lid on software artefacts with the Guardener “Shift left security for web and container-based infrastructures essentially failed ... said James Governor, analyst and co-founder, RedMonk ... Continuous maintenance is becoming mandatory as AI code generation explodes.” | press | 2026-06-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Chainguard homepage “Building from source in a SLSA L3-compliant Factory is how Chainguard ensures that every line is verified, hardened, and traceable.” | official | 2026-06-28 |
| s2 | Chainguard Containers product page “4.8 Stars on G2 ... On average, Chainguard images show ~97.6% fewer vulnerabilities than typical alternatives, and ~80% lower CVE accumulation over time.” | official | 2026-06-28 |
| s3 | Chainguard pricing page “Full access to 2,000+ images (and growing) ... Starts at $19K for a team of 10 ... Contractual CVE SLA (7 days for critical, 14 days for high/med/low) ... Access to STIG-hardened and FIPS-validated images.” | official | 2026-06-28 |
| s4 | Chainguard Image Directory “Search. Pull. Build. ... Categories: All, Featured, Free, AI, Application, Base, Commercial, FIPS, MCP” | official | 2026-06-28 |
| s5 | Chainguard SOC 2 customer story “we saw a unique opportunity to practice what we preach by using our own product for our SOC 2 certification, Chainguard Images, which cut common vulnerabilities and exposures (CVEs) on average by 97.6%.” | official | 2026-06-28 |
| s6 | HireVue FedRAMP customer story “When Hirevue needed to achieve FedRAMP authorization for its core platform ... One of Hirevue's three cloud engineering delivery teams, approximately 30% of that workforce, was dedicated to recurring security patching and maintenance tasks.” | official | 2026-06-28 |
| s7 | Fortune: Chainguard secures $356 million Series D as valuation soars to $3.5 billion “In fiscal 2025, Chainguard grew its ARR sevenfold, reaching $40 million. By the end of fiscal 2026, it expects to ... hitting $100 million ... it counts over 150 customers, including Canva, HPE, and GitLab ... its buyers are the engineering teams building and maintaining open source.” | press | 2026-06-28 |
| s8 | GeekWire: Chainguard lands $356M, now valued at $3.5B “Chainguard raised $140 million in a Series C round at a $1.12 billion valuation less than a year ago. The company has raised $612 million to date ... It has more than 150 customers, including ANZ Bank, Canva, GitLab, Hewlett Packard Enterprise, VPBank, and Wiz.” | press | 2026-06-28 |
| s9 | SecurityWeek: Chainguard Raises Hefty $356M Series D at $3.5 Billion Valuation “Chainguard, a start-up created by ex-Google software engineers ... The cash infusion brings Chainguard's total funding to about $612 million since its $5 million seed in 2021 ... its catalog has grown from 400 to 1,400 images in the past year, pushing revenue from $5 million to $40 million.” | press | 2026-06-28 |
| s10 | BankInfoSecurity: Chainguard Banks $280M for Global Open-Source Security Play “The latest growth financing is non-dilutive and performance-based, meaning that capital is unlocked as Chainguard acquires customers ... a broader platform including virtual machines and secure libraries enables cross-selling.” | press | 2026-06-28 |
| s11 | SecurityBrief: Chainguard named Gartner leader in software supply security “Chainguard has been named a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security and was placed furthest right for Completeness of Vision ... Chainguard Factory ... has processed more than 1 billion unique build manifests.” | press | 2026-06-28 |
| s12 | The New Stack: Clean Container Images, A Supply Chain Security Revolution “CEO Dan Lorenc and CTO Matt Moore made software engineering stops at Google and Microsoft, with Moore also landing for a while at VMware, and Chief Product Officer Kim Lewandowski also did time with Google. Similarly, Distinguished Engineer Ville Aikas has Google and VMware on his resume.” | press | 2026-06-28 |
| s13 | The New Stack: The hunt for truly zero-CVE container images “Chainguard ... uses ... Factory 2.0, and its DriftlessAF open-source approach to rebuild containers and libraries directly from source ... CVEs remain a useful, but imperfect metric, for measuring safety. ... Other zero-CVE image builders, such as Docker with its Docker Hardened Images (DHI)” | press | 2026-06-28 |
| s14 | Computer Weekly: Chainguard tightens lid on software artefacts with the Guardener “Shift left security for web and container-based infrastructures essentially failed ... said James Governor, analyst and co-founder, RedMonk ... Continuous maintenance is becoming mandatory as AI code generation explodes.” | press | 2026-06-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.